@@ -466,6 +466,7 @@ allow virtd_t self:packet_socket create_socket_perms;
466
466
allow virtd_t self:netlink_generic_socket create_socket_perms;
467
467
allow virtd_t self:netlink_kobject_uevent_socket create_socket_perms;
468
468
allow virtd_t self:netlink_route_socket nlmsg_write;
469
+ allow virtd_t self:anon_inode { create map read write };
469
470
470
471
allow virtd_t virt_domain:process { getattr getsched rlimitinh setsched sigkill signal signull transition };
471
472
dontaudit virtd_t virt_domain:process { noatsecure rlimitinh siginh };
@@ -586,6 +587,7 @@ kernel_read_network_state(virtd_t)
586
587
kernel_rw_net_sysctls(virtd_t)
587
588
kernel_read_kernel_sysctls(virtd_t)
588
589
kernel_read_vm_overcommit_sysctl(virtd_t)
590
+ kernel_read_vm_sysctls(virtd_t)
589
591
kernel_request_load_module(virtd_t)
590
592
kernel_search_debugfs(virtd_t)
591
593
kernel_setsched(virtd_t)
@@ -612,6 +614,7 @@ corenet_tcp_connect_soundd_port(virtd_t)
612
614
corenet_rw_tun_tap_dev(virtd_t)
613
615
614
616
dev_rw_sysfs(virtd_t)
617
+ dev_read_cpuid(virtd_t)
615
618
dev_read_urand(virtd_t)
616
619
dev_read_rand(virtd_t)
617
620
dev_rw_kvm(virtd_t)
@@ -634,6 +637,7 @@ files_search_all(virtd_t)
634
637
files_read_kernel_modules(virtd_t)
635
638
files_read_usr_src_files(virtd_t)
636
639
files_mounton_root(virtd_t)
640
+ files_watch_etc_dirs(virtd_t)
637
641
638
642
# Manages /etc/sysconfig/system-config-firewall
639
643
# files_relabelto_system_conf_files(virtd_t)
@@ -1122,6 +1126,9 @@ allow virt_bridgehelper_t self:tcp_socket create_stream_socket_perms;
1122
1126
allow virt_bridgehelper_t self:tun_socket create_socket_perms;
1123
1127
allow virt_bridgehelper_t self:unix_dgram_socket create_socket_perms;
1124
1128
1129
+ allow virt_bridgehelper_t virt_etc_t:dir list_dir_perms;
1130
+ allow virt_bridgehelper_t virt_etc_t:file read_file_perms;
1131
+
1125
1132
manage_files_pattern(virt_bridgehelper_t, svirt_home_t, svirt_home_t)
1126
1133
1127
1134
kernel_read_network_state(virt_bridgehelper_t)
@@ -1165,6 +1172,8 @@ files_read_etc_files(virt_leaseshelper_t)
1165
1172
allow virtlockd_t self:capability dac_override;
1166
1173
allow virtlockd_t self:fifo_file rw_fifo_file_perms;
1167
1174
allow virtlockd_t self:unix_stream_socket create_stream_socket_perms;
1175
+ allow virtlockd_t self:process getsched;
1176
+ allow virtlockd_t self:unix_dgram_socket create_socket_perms;
1168
1177
1169
1178
allow virtlockd_t virtd_t:dir list_dir_perms;
1170
1179
allow virtlockd_t virtd_t:file read_file_perms;
@@ -1188,11 +1197,17 @@ files_runtime_filetrans(virtlockd_t, virtlockd_run_t, file)
1188
1197
1189
1198
can_exec(virtlockd_t, virtlockd_exec_t)
1190
1199
1200
+ kernel_getattr_proc(virtlockd_t)
1201
+ kernel_read_kernel_sysctls(virtlockd_t)
1191
1202
kernel_read_system_state(virtlockd_t)
1192
1203
1204
+ dev_read_sysfs(virtlockd_t)
1205
+
1193
1206
files_read_etc_files(virtlockd_t)
1194
1207
files_list_var_lib(virtlockd_t)
1195
1208
1209
+ logging_send_syslog_msg(virtlockd_t)
1210
+
1196
1211
miscfiles_read_localization(virtlockd_t)
1197
1212
1198
1213
virt_append_log(virtlockd_t)
@@ -1209,6 +1224,8 @@ allow virtlogd_t self:unix_stream_socket create_stream_socket_perms;
1209
1224
allow virtlogd_t virtd_t:dir list_dir_perms;
1210
1225
allow virtlogd_t virtd_t:file read_file_perms;
1211
1226
allow virtlogd_t virtd_t:lnk_file read_lnk_file_perms;
1227
+ allow virtlogd_t self:process getsched;
1228
+ allow virtlogd_t self:unix_dgram_socket create;
1212
1229
1213
1230
can_exec(virtlogd_t, virtlogd_exec_t)
1214
1231
@@ -1220,11 +1237,17 @@ files_runtime_filetrans(virtlogd_t, virtlogd_run_t, file)
1220
1237
allow virtlogd_t virt_common_runtime_t:file append_file_perms;
1221
1238
manage_files_pattern(virtlogd_t, virt_common_runtime_t, virt_common_runtime_t)
1222
1239
1240
+ kernel_getattr_proc(virtlogd_t)
1241
+ kernel_read_kernel_sysctls(virtlogd_t)
1223
1242
kernel_read_system_state(virtlogd_t)
1224
1243
1244
+ dev_read_sysfs(virtlogd_t)
1245
+
1225
1246
files_read_etc_files(virtlogd_t)
1226
1247
files_list_var_lib(virtlogd_t)
1227
1248
1249
+ logging_send_syslog_msg(virtlogd_t)
1250
+
1228
1251
miscfiles_read_localization(virtlogd_t)
1229
1252
1230
1253
sysnet_dns_name_resolve(virtlogd_t)
0 commit comments